Skip to content
GoogleGHSA-24w6-q4hq-mjfr

ENGAGE - Server Displaying Sensitive Information

LowPublished Jan 10, 2025 · updated Jan 25, 2025

### Summary A vulnerability was found in engage platform, where an internal server error message exposes sensitive information about the servers, including SQL table which could lead to SQL injection. ### Severity Low - This vulnerability discloses partial information that is not immediately exploitable. ### Proof of Concept - Go to https://www.letsengage.com/google-form - File the form, enter text with some strange string encoding (I don’t exactly know what, looking at the error, something that latin1_swedish_ci cannot represent) in one of the input fields (I don’t know which one). - Go to the end of the form by filing all the inputs. - Click submit. - … - Get the error message. ### Timeline **Date reported**: 09/20/2024 **Date fixed**: **Date disclosed**: 1/10/2025

GitHub advisory

Affected versions

PackageAffectedFixed in
Engage
Product
all versionsNo fix yet
Details and references

More Google advisories

All Google
Advisory
Integer Overflow in eBPF DEVMAP map_delete_elem Leads to Out-of-Bounds
High7.8Jan 9, 2025
Linux Kernel: Integer Overflow in eBPF XSK map_delete_elem Leads to Out-of-Bounds
High7.8Jan 9, 2025
Linux Kernel: Out of bounds Write in ksmbd_vfs_stream_write
Critical9.8Jan 9, 2025
Linux Kernel: Out of bounds Read in ksmbd_vfs_stream_read
Critical9.1Jan 9, 2025
Apple: WebKit Canvas Denoising
MediumDec 26, 2024
MacPorts: Remote Code Execution
MediumDec 23, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.